Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
The Compliance Brief · Issue 3

A CVSS 10 in Entra ID and a breach that grew tenfold

Free weekly email

This went to subscribers on August 25. Get the next one.

One email every Tuesday: what changed in security and compliance that week, and what it means if you sell to enterprise buyers.

Free. Unsubscribe in one click, and replies reach Jacob directly. Read the latest issue or browse the archive.

Two things this week actually change what you do on Monday morning: a maximum-severity hole in the identity service most of your customers log in through, and a supply chain attack that runs code while you compile rather than while you ship. The rest of the feed was breach notices, and I picked the three that say something useful about how vendors get named, how numbers get revised, and how much a self-scored assessment is worth. Plenty of large stories got left out because they do not touch a Canadian SaaS vendor sitting in a US security review.

Microsoft patches a 10.0 in Entra ID

Source: Help Net Security

Microsoft patched CVE-2026-69836, a remote code execution flaw in Entra ID carrying a CVSS score of 10.0, which was initially reported as exploited in the wild. Entra ID, formerly Azure Active Directory, handles logins and access to Microsoft 365, Azure and connected third-party applications. The issue was found by a Microsoft principal security engineer and allows an unauthenticated attacker to reach the service.

Our take

The patch is Microsoft's problem, but the questionnaire is yours. If your product federates with Entra or your own staff sign in through it, assume a buyer's security team asks this week whether you were affected, and have an answer that references sign-in logs and privileged service principals rather than a shrug. I would spend an hour reviewing which app registrations in your tenant hold consented permissions you would not grant again today.

Rust crates that ran malware at compile time

Source: The Hacker News

The Rust Project removed malicious versions of three widely used crates from crates.io after a compromised maintainer account published releases adding a typosquatted dependency. The dependency's build script downloaded and executed a remote payload during compilation. The affected releases were arrayref 0.3.10, internment 0.8.7 and append-only-vec 0.1.9, from crates with 245 million downloads between them.

Our take

Build-time execution means the target was your CI runner and whatever credentials live on it, not your production containers, so scanning the shipped artifact would have found nothing. Pinned versions and committed lockfiles are the boring control that stops this, and both are things a SOC 2 auditor will happily take evidence of. If your build agents hold long-lived cloud keys or a signing certificate, that is the finding to fix before the next review, whether or not you write Rust.

SickKids gets hit through somebody else's software

Source: BleepingComputer

Toronto's Hospital for Sick Children disclosed a security incident that exposed personal information belonging to some current and former employees and job applicants. The hospital attributes the exposure to a flaw in third-party software. Clinical systems and patient records were not affected.

Our take

Read that reporting from the other side of the contract, because in a story like this you are the third-party software. Your notification clock, your evidence obligations and your willingness to be named are set by whatever your MSA says today, and most Canadian SaaS contracts I read are vague on all three. Fix the clause before an incident, since negotiating disclosure terms during one goes badly for the vendor every time.

CareCloud's count goes from 350,000 to 3.7 million

Source: SecurityWeek

CareCloud's data breach was initially believed to affect roughly 350,000 people. The HHS breach tracker now shows the impact at about 3.7 million individuals, more than ten times the first estimate.

Our take

Early impact numbers come out of whatever the team could count in week one, and they almost always move in one direction. If you ever have to send that notice, publish the scope you can defend and say explicitly that the figure is preliminary, because a revision that looks like a correction is survivable and one that looks like a cover-up is not. Buyers with HIPAA obligations of their own remember the second number, not the first.

Defence contractors do not believe their own CMMC scores

Source: Infosecurity

US defence contractors are reporting doubts about the accuracy of their own self-assessment scores under CMMC Phase I. Those scores have reached an all-time high at the same time.

Our take

Self-scoring drifts upward when there is money attached, which is the whole reason assessment phases exist. For Canadian firms this matters twice: if you subcontract to a US prime your inflated score becomes their problem in an audit, and CPCSC is arriving with the same structure at home. My advice is to score yourself against what an assessor would accept as evidence, then keep the gap list rather than the flattering number.

Nothing in the regulatory column this week moves the needle for a Canadian vendor, though the SEC's proposed crypto asset rules are worth a skim if you touch digital assets. I will pick that thread up if the comment period produces anything concrete.

Jacob

Share this issue LinkedIn X Email

Free weekly email

Get the next issue on Tuesday

One email a week from Jacob Masse: the security and compliance stories that changed something that week, and what each one means if you sell software to enterprise buyers. Five stories, a take on each, five minutes to read.

Free. Unsubscribe in one click, and replies reach Jacob directly.

Go deeper

Every past issue · RSS feed